Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Several issues have been identified that affect XenServer 8.4 and XenServer 9. Collectively, these issues may allow a malicious privileged user in a guest VM to compromise or crash the host.
Affected productsXenServer, These issues affect both XenServer 8.4 and XenServer 9; versions of the XenServer Terraform provider versions before version 0.3.0 are affected by the Terraform issue.
Vendor guidance
We have pushed updates to both the Early Access and Normal update channels of each of XenServer 8.4 and XenServer 9. We recommend that customers update to the latest version from their chosen channel following the ins...
Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows contain the vulnerabilities mentioned below
Affected productsCitrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, The following supported versions of Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows are affected by CVE-2026-53565: Citrix Secure Access Client for Windows versions BEFORE 26.6.1.20 Citrix Endpoint Analysis Client for Windows versions BEFORE 26.5.1.7 The following supported versions of Citrix Secure Access Client for Windows are affected by CVE-2026-53566: Citrix Secure Access Client for Windows versions BEFORE 26.6.1.20
Fixed versionsCitrix Secure Access Client for Windows 26.6.1.20 and later releases, Citrix Endpoint Analysis Client for Windows 26.5.1.7 and later releases
Vendor guidance
Cloud Software Group strongly urges customers of Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client to install the relevant updated versions as soon as possible: Citrix Secure Access Client fo...
Cloud Software Group strongly urges affected customers of Citrix Workspace App for Mac to install the relevant updated versions of Citrix Workspace App for Mac as soon as possible:
Affected productsCitrix Workspace App for Mac, The following supported versions of Citrix Workspace App for Mac are affected by the vulnerability: Citrix Workspace app for Mac before 2607
Fixed versionsCitrix Workspace app for Mac 2607 and later
The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities:
Affected productsNetScaler ADC and NetScaler Gateway, The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities: NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32 NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21 NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277
Fixed versionsNetScaler ADC and NetScaler Gateway 14.1-73.32 and later releases, NetScaler ADC and NetScaler Gateway 13.1-63.21 and later releases of 13.1, NetScaler ADC 14.1-FIPS 14.1-73.32 FIPS and later releases of 14.1-FIPS, NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.277 and later releases of 13.1-FIPS and 13.1-NDcPP
Vendor guidance
Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible. NetScaler ADC and NetScaler Gateway 14.1-73.32 and later rele...
Several issues have been identified that affect XenServer 8.4 and XenServer 9. Collectively, these issues may allow a malicious privileged user in a guest VM to compromise or crash the host.
Affected productsXenServer, These issues affect XenServer 8.4 and XenServer 9.
Vendor guidance
We have pushed updates to both the Early Access and Normal update channels of each of XenServer 8.4 and XenServer 9. We recommend that customers update to the latest version from their chosen channel following the ins...
NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities mentioned below:
Affected productsNetScaler ADC and NetScaler Gateway, The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities: NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61 NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18 NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272 Note: Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities. Customers need to upgrade these NetScaler instances to the recommended NetScaler builds to address the vulnerabilities. This bulletin only applies to customer-managed NetScaler ADC and NetScaler Gateway. Cloud Software Group upgrades the Citrix-managed cloud services and Citrix-managed Adaptive Authentication with the necessary software updates. Blog Cloud Software Group team has published a related blog at: https://community.citrix.com/techzone-blogs/110_security-updates/security-update-for-citrix-netscaler-and-netscaler-gateway-customers-r1570/ which contains further context.
Fixed versionsNetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases, NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1, NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS, NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
Vendor guidance
Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible. NetScaler ADC and NetScaler Gateway 14.1-72.61 and later rele...
NetScaler ADC and NetScaler Gateway contain the vulnerabilities mentioned below:
Affected productsNetScaler ADC and NetScaler Gateway, The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities: NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-43.56 NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-58.32 NetScaler ADC 13.1-FIPS and NDcPP BEFORE 13.1-37.235-FIPS and NDcPP NetScaler ADC 12.1-FIPS BEFORE 12.1-55.328-FIPS Note: NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End Of Life (EOL) and are vulnerable. Customers are recommended to upgrade their appliances to one of the supported versions that address the vulnerabilities.
Fixed versionsNetScaler ADC and NetScaler Gateway 14.1-43.56 and later releases, NetScaler ADC and NetScaler Gateway 13.1-58.32 and later releases of 13.1, NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.235 and later releases of 13.1-FIPS and 13.1-NDcPP, NetScaler ADC 12.1-FIPS 12.1-55.328 and later releases of 12.1-FIPS
Vendor guidance
Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible. NetScaler ADC and NetScaler Gateway 14.1-43.56 and later rele...
An issue has been identified in the XenServer management API SDK that may allow an attacker on the management network who is able to intercept specific HTTPS requests within a higher-level operation to be able to act with the privileges of the intercepted administrator. This i...
Affected productsXenServer, This issue affects XenCenter versions before 2026.4.0 and, for PowerShell and C# clients only, SDK versions before 26.15.0. As the issue is in the client-side (XenCenter and SDK) code, it is independent of the version of XenServer that is in use.
Vendor guidance
We have released updated versions of both XenCenter and the SDK. We recommend that customers update their existing XenCenter to the latest version using the built-in update functionality as documented at https://docs....
AMD has disclosed an issue in AMD Zen 2-based CPUs that may allow code in a guest VM to compromise the host. Although this hardware vulnerability is not an issue in the XenServer product itself, for the convenience of customers we are providing an update that mitigates this CP...
Affected productsXenServer, This issue affects XenServer 8.4. (Note that XenServer 9 is in Public Preview; releases in preview state are not intended for production use and so are not covered by security bulletins until they exit preview state)
Vendor guidance
We have pushed updates to both the Early Access and Normal update channels of XenServer 8.4. We recommend that customers update to the latest version from their chosen channel following the instructions at https://doc...
This issue only affects certain AMD CPUs; customers who are running Intel-based systems are not affected by this issue.
Affected productsXenServer, These issues affect XenServer 8.4. (Note that Citrix Hypervisor 8.2 CU1 is now End of Life (EoL) and so no longer receives security updates or security bulletins.)
Vendor guidance
We have pushed updates to both the Early Access and Normal update channels of XenServer 8.4. We recommend that customers update to the latest version from their chosen channel following the instructions at https://doc...
Several issues have been identified in XenServer 8.4 that collectively may allow privileged code in a guest VM to compromise or crash the host.
Affected productsXenServer, These issues affect XenServer 8.4. (Note that Citrix Hypervisor 8.2 CU1 is now End of Life (EoL) and so no longer receives security updates or security bulletins.)
Vendor guidance
We have pushed updates to both the Early Access and Normal update channels of XenServer 8.4. We recommend that customers update to the latest version from their chosen channel following the instructions at https://doc...
Two issues have been identified that affect XenServer 8.4 that each may allow a logged-in host administrator to escalate their privileges to a higher level than defined by their RBAC role. These issues have the following identifiers:
Affected productsXenServer, These issues affect XenServer 8.4. (Note that XenServer 9 is in Public Preview; releases in preview state are not intended for production use and so are not covered by security bulletins until they exit preview state.)
Vendor guidance
We have pushed updates to both the Early Access and Normal update channels of XenServer 8.4. We recommend that customers update to the latest version from their chosen channel following the instructions at https://doc...
An issue that may, in some circumstances, allow a malicious privileged user in a guest VM to compromise the host. This issue has the following identifier:
Affected productsXenServer, These issues affect XenServer 8.4. (Note that XenServer 9 is in Public Preview; releases in preview state are not intended for production use and so are not covered by security bulletins until they exit preview state.)
Vendor guidance
We have pushed updates to both the Early Access and Normal update channels of XenServer 8.4. We recommend that customers update to the latest version from their chosen channel following the instructions at https://doc...
NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities mentioned below:
Affected productsNetScaler ADC and NetScaler Gateway, The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities: CVE-2026-3055: NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-60.58 NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-62.23 NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.262 CVE-2026-4368: NetScaler ADC and NetScaler Gateway 14.1-66.54 Note: CVE-2026-4368 only impacts build version 14.1-66.54.
Fixed versionsNetScaler ADC and NetScaler Gateway 14.1-66.59 and later releases, NetScaler ADC and NetScaler Gateway 13.1-62.23 and later releases of 13.1, NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.262 and later releases of 13.1-FIPS and 13.1-NDcPP
Vendor guidance
CVE 2026-3055 was identified internally through our ongoing security reviews and broader efforts to strengthen the security of the product. Cloud Software Group strongly urges affected customers of NetScaler ADC and N...
An issue has been identified in XenServer 8.4 which, when starting a VM on a host with limited available memory, may allow a privileged user in that newly starting VM to access memory data of a previously terminated VM. This issue has the following identifier:
Affected productsXenServer, This issue affects XenServer 8.4. (Note that XenServer 9 is in Public Preview; releases in preview state are not intended for production use and so are not covered by security bulletins until they exit preview state.)
Vendor guidance
We have pushed updates to both the Early Access and Normal update channels of XenServer 8.4. We recommend that customers update to the latest version from their chosen channel following the instructions at https://doc...
An issue has been identified in XenServer 8.4 that may allow privileged code in a guest VM to compromise the host. This issue has the following identifier:
Affected productsXenServer, This issue affects XenServer 8.4. (Note that XenServer 9.0 is in Public Preview; releases in preview state are not intended for production use and so are not covered by security bulletins until they exit preview state.)
Vendor guidance
We have pushed updates to both the Early Access and Normal update channels of XenServer 8.4. We recommend that customers update to the latest version from their chosen channel following the instructions at https://doc...
NetScaler ADC and NetScaler Gateway are affected by the vulnerability mentioned below:
Affected productsNetScaler ADC and NetScaler Gateway, The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities: NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-56.73 NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-60.32 NetScaler ADC 13.1-FIPS and NDcPP BEFORE 13.1-37.250-FIPS and NDcPP NetScaler ADC 12.1-FIPS and NDcPP BEFORE 12.1-55.333-FIPS and NDcPP Note: NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End Of Life (EOL) and are vulnerable. Customers are recommended to upgrade their appliances to one of the supported versions that address the vulnerabilities.
Fixed versionsNetScaler ADC and NetScaler Gateway 14.1-56.73 and later releases, NetScaler ADC and NetScaler Gateway 13.1-60.32 and later releases of 13.1, NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.250 and later releases of 13.1-FIPS and 13.1-NDcPP, NetScaler ADC 12.1-FIPS and 12.1-NDcPP 12.1-55.333 and later releases of 12.1-FIPS and 12.1-NDcPP
Vendor guidance
Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible. NetScaler ADC and NetScaler Gateway 14.1-56.73 and later rele...
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.